PlumbTrackLive demoGRC Risk System

← internal audit

Audit — SC-28 — Protection of Information at Rest

Framework: NIST SP 800-53 Rev.5 SC-28 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Review the data-at-rest policy to identify which information, by classification, must be encrypted at rest and the approved mechanisms (full-disk, volume, database TDE, field-level).
Test Verify encryption at rest is enabled across servers, endpoints, databases, backups, and removable media that hold sensitive data (CIS Control 3.11).
Test Sample specific systems to confirm encryption is actually active, e.g., BitLocker/LUKS status on an endpoint/server and Transparent Data Encryption status on a database.
Examine Confirm keys protecting data at rest are managed separately from the encrypted data and are protected consistent with the SC-12 key management controls.
Interview Ask administrators how at-rest encryption coverage is monitored and how exceptions (unencrypted stores of sensitive data) are identified, tracked, and remediated.
Examine Verify backups and archived/offsite media are encrypted and that integrity protection (e.g., hashing) is applied where the control requires integrity as well as confidentiality.